With all these elastic search instances running open to the public I have the feeling that with IPv6 this will get worse as NAT no longer protects you.
With all these elastic search instances running open to the public I have the feeling that with IPv6 this will get worse as NAT no longer protects you.
Their requirement is probably for their addresses to be globally unique.
Historical addressing plans being what they are, they probably have sparse assignments across all blocks. Re-numbering existing systems is a non-trivial exercise with high costs. There is no benefit to them to doing this, and we have known this exhaustion is coming for literally decades now.
Just because they're not in use on the Internet, doesn't mean they're not in use.
> With all these elastic search instances running open to the public I have the feeling that with IPv6 this will get worse as NAT no longer protects you.
Stateful firewalls protect you. NAT does not.
You're not the first person to ask this, and the answer is: not nearly enough.
Demand for IPv4 is orders of magnitude larger than the current address space. There is no level of freeing up addresses that can make this problem go away. At most we're buying us a few months until we run out again.
I'd wager most home networks are protected only by the fact that they use NAT. ISPs are getting better about shipping routers with firewalls on by default, but it's still not there.
(Have you ever seen even an old IPv4-only home router that didn't include a firewall? I haven't.)
On a real firewall, generally you don't reroute a port to a different IP, you just pass or fail the packet.
Other large holders include Apple, Ford, Prudential Insurance and the USPS.
More easy answers to similar questions here: https://en.wikipedia.org/wiki/List_of_assigned_/8_IPv4_addre...